feat: Updates for 1.20.1 - #498
Conversation
8469efb to
31027d2
Compare
Signed-off-by: Mike McKiernan <mmckiernan@nvidia.com>
31027d2 to
b140edc
Compare
Documentation preview |
cdesiniotis
left a comment
There was a problem hiding this comment.
Great work as always @mikemckiernan!
|
|
||
| JIT-CDI mode injects MIG management capability device nodes when the `NVIDIA_MIG_CONFIG_DEVICES` or `NVIDIA_MIG_MONITOR_DEVICES` environment variable is set to `all` in a privileged container. | ||
| This injects the `/dev/nvidia-caps/` device nodes that tools such as `nvidia-smi mig` need to create, destroy, and monitor MIG partitions. | ||
| The container must have `CAP_SYS_ADMIN`, and the host must use cgroup v2. |
There was a problem hiding this comment.
IIRC this change does not depend on cgroup v2, so I would prefer to omit this clause. @henry118 could you confirm?
| The container must have `CAP_SYS_ADMIN`, and the host must use cgroup v2. | |
| The container must have `CAP_SYS_ADMIN`. |
There was a problem hiding this comment.
Strictly speaking, CAP_SYS_ADMIN is the only requirement here - not even "privileged" container.
Note that when a container is "privileged" (either with --privileged docker CLI option, or privileged: true in k8s pod spec), all devices under /dev will be automatically injected by runtime (containerd) by default, regardless the toolkit.
|
|
||
| JIT-CDI mode injects MIG management capability device nodes when the `NVIDIA_MIG_CONFIG_DEVICES` or `NVIDIA_MIG_MONITOR_DEVICES` environment variable is set to `all` in a privileged container. | ||
| This injects the `/dev/nvidia-caps/` device nodes that tools such as `nvidia-smi mig` need to create, destroy, and monitor MIG partitions. | ||
| The container must have `CAP_SYS_ADMIN`, and the host must use cgroup v2. |
There was a problem hiding this comment.
Strictly speaking, CAP_SYS_ADMIN is the only requirement here - not even "privileged" container.
Note that when a container is "privileged" (either with --privileged docker CLI option, or privileged: true in k8s pod spec), all devices under /dev will be automatically injected by runtime (containerd) by default, regardless the toolkit.
| The following command injects both MIG config and monitor devices: | ||
|
|
||
| ```console | ||
| $ docker run --rm --runtime=nvidia --privileged \ |
There was a problem hiding this comment.
So here it's better to use --cap-add=SYS_ADMIN option instead of --privileged. Since mig config/monitor devices will be always available to the container in the latter case.
| ### Fixes and Features | ||
|
|
||
| - CDI specifications and JIT-CDI mode now inject MIG management capability devices into containers. | ||
| Set the `NVIDIA_MIG_CONFIG_DEVICES` or `NVIDIA_MIG_MONITOR_DEVICES` environment variable to `all` in a privileged container to inject the `/dev/nvidia-caps/` device nodes for MIG partition management. |
There was a problem hiding this comment.
Same here about the "privileged" wording
Signed-off-by: Mike McKiernan <mmckiernan@nvidia.com>
No description provided.